Showing posts with label data management. Show all posts
Showing posts with label data management. Show all posts

Tuesday, August 14, 2012

FinSpy Spyware Appears in 10 Countries

It is one of the more elusive commercial cyber-espionage tools available.

It is marketed as a way for governments to spy on criminals and for over a year, virus hunters unsuccessfully tried to track it down.

Now it is popping up across the globe, from Qatar to an Amazon server in the United States.

FinFisher is a spyware product manufactured by the Gamma Group, a British company that sells surveillance technology. It says its spyware offers “world-class offensive techniques for information gathering.”

According to FinFisher’s promotional materials, the spyware can be “used to access target systems, giving full access to stored information with the ability to take control of the target system’s functions to the point of capturing encrypted data and communications.”

Security researchers who studied the spyware last month said it can grab images of users’ computer screens, record their Skype chats, remotely turn on cameras and microphones, and log keystrokes.

The Gamma Group markets FinFisher as a way for government law enforcement and intelligence agencies to keep track of criminals, but the researchers’ findings suggested that it was being used more broadly.

The spyware first attracted attention in March 2011 after protesters in Egypt raided the country’s state security headquarters and found an offer to buy FinFisher for 287,000 euros, or $353,000.

Then in May of this year, pro-democracy Bahraini activists, one in London, another in Washington and one in the Bahraini capital, Manama, started receiving suspicious e-mails, which they passed to a Bloomberg reporter.

Read the full article here: Elusive FinSpy Spyware Pops Up in 10 Countries - NYTimes.com

Friday, March 23, 2012

Data Security not a Priority - The Information Risk Maturity Index

Data breaches will continue to expose European businesses to unnecessary risk and damage business reputations unless action is taken now to improve the management and protection of sensitive business information, says a new report by Iron Mountain and PwC.

The study highlights an urgent need for a change in employee behaviour and a cultural shift among senior executives if organizations are to overcome the complacency, negligence and lack of shared responsibility uncovered by the study.

PwC surveyed senior managers at 600 leading European businesses to compile the Information Risk Maturity Index.

The scores, assessed for France, Germany, Hungary, the Netherlands, Spain and the UK, suggest that many businesses are woefully unprepared to address and manage information risks such as data breaches, data loss and non-compliance.

The average score for European companies was 40.6 against an ideal score of 100.

The report, launched at Iron Mountain’s first European Information Risk Summit, reveals that:
  • Only around half of mid-sized businesses consider the loss of sensitive information as one of their top three business risks.
  • Less than a quarter (24 percent) of the companies surveyed were aware as to whether or not they had experienced a data breach in the last three years.
  • A mere 1 percent of respondents consider information risk to be the responsibility of every employee, while nearly two thirds (60 percent) concede that they do not know whether their employees have the right tools to protect information.
  • Only 13 percent consider information risk to be a boardroom issue, while around a third (35 percent) view all information risk – whether related to paper or digital information – as the responsibility of the IT department. This tendency to view information risk as an IT issue was found to be widespread, with 59 percent responding to a data breach by installing additional technology.
  • Just a third (36 percent) of companies have assigned responsibility for information risk to a specific individual or team whose effectiveness is monitored.
Marc Duale, President of International at Iron Mountain, said the report was a wake-up call for European businesses: “It is time for businesses to move from a culture of information apathy and neglect to a culture of information responsibility. Fail to act and you expose your customers to serious information risk while potentially leaving your company open to the risk of irreparable reputational damage.”

Read the report (PDF)

Friday, October 21, 2011

BYOD: ‘bring your own device’ How will it impact your company

In case you haven't heard, the Bring Your Own device to work strategy is doing the rounds in the more enlightened corporate IT world and is a very attractive option for Developers, Administrators and other IT geeks of that ilk.

That aside, as a non-geek, BYOD will require serious attention to the infrastructure and support policies within your organisation.

The one really good reason not to let employees use their own smartphone, notebook or tablet at work, is because it creates an IT management nightmare.

Firstly or blatantly, there are inherent security and regulatory compliance risks. Unless you have complete control or have great faith the responsibility of IT geeks to protect their own assets.

Even if you restrict and /or allow certain products or technologies that people can bring and use, it will be next to impossible to make sure everyone keeps their machines updated with the proper OS and application patches.

If you use the argument that BYOD will save the company money on assets, their maintenance and their depreciation, you may be disappointed. Many businesses supporting BYOD expect employees to buy and support devices at their own expense but the boundary between the BYOD asset an dthe infrastructure and security policies behind that may be blurred.

Consequently, there is a high risk of holes opening up in your Securoty, DMZ and Firewall. The money not spent on assets may have to be diverted to protect the infrastructure and will require the development of new IT management policies. Can you say your organization is BOYD ready?

To simplify small and midsize businesses (SMEs) should be prepared to sense BYOD and it's impact in the following ways.

#1: Your technology upgrade cycles will be shorter
Most smartphones are turned over every one or two years, because of carrier contracts. That means employees will be exposed to new features more quickly and be able to keep up with business enhancing features made available on open platforms e.g. Skype, Social media, etc.

#2: You will need to consider supporting or including more devices, not fewer
Even if your company chooses not to let employees bring their own smartphones, consumer tablets or notebooks into their work setting, it will need to consider adding more devices to the menu that allows people to work whilst travelling. Consider this an evolution of your corporate benefits or perks strategies. People should be able to choose their own device for work, even if they don’t own them outright.

#3: You need to rethink how you distribute applications
Thanks to Apple, most of us have become really familiar with the idea that you can download pretty much any application you need from searchable store. Over time, employees will come to expect the same from our IT team. Updates and upgrades will be enforced through alerts, much like the store concept.

#4: You need to raise your game on mobile security
Mobile malware and antivirus software packages exist, but they haven’t been widely used. If you allow people to bring their own mobile device, that needs to change. What’s more, your organisation will need to govern what data can and cannot be downloaded locally. That’s especially true in certain industries, especially healthcare or financial services where the Data Protection Act is very pertinent.

#5: You need to rethink the concept of mobility.
IDC expects the number of mobile workers worldwide to surpass 1.2 billion by 2013. Why would you provision someone with a desktop computer, even if it is a person who traditionally works in a back office position, if there is a chance that he or she might need greater flexibility in the future?

Forrester Research predicts that up to 60 percent of information workers will need to work in some location outside their office during the average workweek. Does that number fit well with your asset projections for notebook computers, media tablets or smartphones in your organisation?

Bring Your Own Device to work certainly has an allure and attraction from an financial asset management perspective and as a motivator for Developers and IT Geeks but have we thought this all the way through and are we, and our organisations really ready to adopt this strategy.

Saturday, March 5, 2011

ENISA: EU cyber security agency warns of new cookies risk

The EU’s cyber security agency ENISA has published a position paper on the security and privacy concerns regarding new types of online cookies.

The advertising industry has led the drive for new, persistent and powerful cookies, with privacy-invasive features for marketing practices and profiling.

The Agency recommends that both the user browser and the origin server must assist informed consent; that users should be able to easily manage their cookies; and that users should be provided with another service channel if they do not accept cookies.

The Agency recommends a thorough study of different interpretations in the Member States, once the Directive 2009/136/EC has been implemented, by 25 May 2011.

The new Agency Position Paper identifies and analyses cookies in terms of security vulnerabilities and the relevant privacy concerns. Cookies were originally used to facilitate browser-server interaction.
 
Lately, driven by the advertising industry, they are used for other purposes; e.g. advertising management, profiling, tracking, etc. The possibilities to misuse cookies both exist and are being exploited.

The new type of cookies support user-identification in a persistent manner and do not have enough transparency of how they are being used. Therefore, their security and privacy implications are not easily quantifiable.

The Executive Director of ENISA, Prof. Udo Helmbrecht states:
”Much work is needed to make these next-generation cookies as transparent and user-controlled as regular HTTP cookies, to safeguard the privacy and security aspects of consumers and business alike”.

Wednesday, November 24, 2010

Secure Document Management using RFID: Breeze and Sharepoint



RFID tags have made their way into document management to allow them to be physically tracked, as they move through an organisation.

An interesting way to know just where every document is at any given time and who’s holding it and who's working on it.

The video describes the process and shows the requirement for an RFID reader in the paper tray.

Monday, December 14, 2009

Picture This! Artwork, Graphics and Visualisation for better data management

"A good sketch is better than a long speech..." -- a quote often attributed to Napoleon Bonaparte
The ability to visualise the implications of data, is as old as humanity itself.

Yet due to the vast warehouses (quantities, sources, and silos) of data being carried around our global economy at an ever increasing rate, the need for superior visualisation is growing dramatically.

Over time we will naturally migrate toward superior visualisations to cope with this oceanic tide of information or be lost in the tidal wave that engulfs us.

Our ability to deal with data, in a non-visual and graphical nature, is self limiting. Whereby the human becomes the squeeze point where data grinds to a complete halt, awaiting further decisive action.

Neanderthal Approach
Since the days of the cave paintings, graphic depiction has always been an integral part of how people think, communicate, and make sense of the world. This modern world is no different, new information systems are at the heart of all management processes and organisational activities.

The good news is that even in a world of information surplus and overspill, we can draw upon deep human habits on how to visualise information to make sense of a dynamic reality and enable understanding and comprehension.

Moore's Law
The quality, timeliness, granularity, and volume of data has increased greatly. Also, with the ever improving assistance of Moore's Law, we have the power to recombine and analyse the vast stream of information at a price point that makes even very advanced visualisation techniques within the reach of any business.

The Power of Three
Working with my clients, I've seen three primary benefits of superior graphic representation:

1. Greater visualisation is more efficient — they let people look at and absorb vast quantities of data quickly.
2. Graphics or visual representations can help an analyst, or a group, achieve more insight into the nature of a problem and discover new understanding.
3. Better visualisation can help create a shared view of a situation and it will establish a shared alignment on needed actions.

Data Combination
In addition to arranging the information to create shared understanding, visualisation gives us the ability to combine data to create a new insight, quickly and clearly

Mapping Tools
The quality of cheap mapping tools and the availability of vast quantities of free or inexpensive data is growing. The planet is becoming "smart" in the sense that we can track, monitor and see much more of both the built and the natural environment.

The Challenge
The challenge is that if management teams do not consciously build in great visualisations, their organisations will waste an inordinate amount of time, sifting through the quagmire of bits, and may not even get to the effective insights they need.

Collaboration
Perhaps most perniciously, people will be too focused on their own part of the puzzle, never getting to the shared and collaborated understanding that allows teams to take the right action in a tight time-frame.

Questions?
Ask yourself the following questions:

1. Is there a simple map or maps of information that could make my life easier?
2. Do we have the ability to take this data mountain and synthesise it into these new forms?
3. How much time does the organisation waste arguing about the facts instead of deepening understanding or crafting solutions?